MSTIC, CDOC, 365 Defender Research Team. (2021, January 20). Deep dive into the Solorigate second-stage activation: From SUNBURST to TEARDROP and Raindrop . Retrieved January 22, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.006 DCSync |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used privileged accounts to replicate directory service data with domain controllers. |
| T1012 Query Registry |
MalwareTEARDROP | TEARDROP checked that |
| T1018 Remote System Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used AdFind to enumerate remote systems. |
| T1027 Obfuscated Files or Information |
MalwareTEARDROP | TEARDROP created and read from a file with a fake JPG header, and its payload was encrypted with a simple rotating XOR cipher. |
| T1027.002 Software Packing |
MalwareRaindrop | Raindrop used a custom packer for its Cobalt Strike payload, which was compressed using the LZMA algorithm. |
| T1027.013 Encrypted/Encoded File |
MalwareRaindrop | Raindrop encrypted its payload using a simple XOR algorithm with a single-byte key. |
| T1036 Masquerading |
MalwareRaindrop | Raindrop was built to include a modified version of 7-Zip source code (including associated export names) and Far Manager source code. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSUNBURST | SUNBURST created VBScripts that were named after existing services or folders to blend into legitimate activities. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRaindrop | Raindrop was installed under names that resembled legitimate Windows file and directory names. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTEARDROP | TEARDROP files had names that resembled legitimate Window file and directory names. |
| T1047 Windows Management Instrumentation |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used WMI for the remote execution of files for lateral movement. |
| T1057 Process Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used multiple command-line utilities to enumerate running processes. |
| T1059.005 Visual Basic |
MalwareSUNBURST | SUNBURST used VBScripts to initiate the execution of payloads. |
| T1070 Indicator Removal |
MalwareSUNBURST | SUNBURST removed HTTP proxy registry values to clean up traces of execution. |
| T1070.006 Timestomp |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 modified timestamps of backdoors to match legitimate Windows files. |
| T1070.007 Clear Network Connection History and Configurations |
MalwareSUNBURST | SUNBURST also removed the firewall rules it created during execution. |
| T1070.009 Clear Persistence |
MalwareSUNBURST | SUNBURST removed IFEO registry values to clean up traces of persistence. |
| T1112 Modify Registry |
MalwareSUNBURST | SUNBURST had commands that allow an attacker to write or delete registry keys, and was observed stopping services by setting their |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRaindrop | Raindrop decrypted its Cobalt Strike payload using an AES-256 encryption algorithm in CBC mode with a unique key per sample. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTEARDROP | TEARDROP was decoded using a custom rolling XOR algorithm to execute a customized Cobalt Strike payload. |
| T1195.002 Compromise Software Supply Chain |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 gained initial network access to some victims via a trojanized update of SolarWinds Orion software. |
| T1218.011 Rundll32 |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `Rundll32.exe` to execute payloads. |
| T1218.011 Rundll32 |
MalwareSUNBURST | SUNBURST used Rundll32 to execute payloads. |
| T1482 Domain Trust Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used the `Get-AcceptedDomain` PowerShell cmdlet to enumerate accepted domains through an Exchange Management Shell. They also used AdFind to enumerate domains and to discover trust between federated domains. |
| T1546.003 Windows Management Instrumentation Event Subscription |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used a WMI event filter to invoke a command-line event consumer at system boot time to launch a backdoor with `rundll32.exe`. |
| T1546.012 Image File Execution Options Injection |
MalwareSUNBURST | SUNBURST created an Image File Execution Options (IFEO) Debugger registry value for the process |
| T1555 Credentials from Password Stores |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used account credentials they obtained to attempt access to Group Managed Service Account (gMSA) passwords. |
| T1558.003 Kerberoasting |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained Ticket Granting Service (TGS) tickets for Active Directory Service Principle Names to crack offline. |
| T1560.001 Archive via Utility |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used 7-Zip to compress stolen emails into password-protected archives prior to exfltration; APT29 also compressed text files into zipped archives. |
| T1587.001 Malware |
CampaignSolarWinds Compromise | For the SolarWinds Compromise, APT29 used numerous pieces of malware that were likely developed for or by the group, including SUNBURST, SUNSPOT, Raindrop, and TEARDROP. |
| T1680 Local Storage Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `fsutil` to check available free space before executing actions that might create large files on disk. |
| T1685 Disable or Modify Tools |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used the service control manager on a remote system to disable services associated with security monitoring products. |
| T1685.001 Disable or Modify Windows Event Log |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29, used `AUDITPOL` to prevent the collection of audit logs. |
| T1686 Disable or Modify System Firewall |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used `netsh` to configure firewall rules that limited certain UDP outbound packets. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.